CVE-2022-27924 is a critical vulnerability affecting Zimbra Collaboration Suite (ZCS) versions 8.8.15 and 9.0, allowing unauthenticated attackers to inject arbitrary memcache commands. This flaw enables the overwrite of cached entries, posing a significant risk to affected systems. With a CVSS score of 7.5 (HIGH), the vulnerability is easily exploitable over the network with low attack complexity, potentially leading to high impact on integrity without user interaction. This CVE is actively exploited in the wild, including in known ransomware campaigns, and has garnered substantial community discussion and media coverage, highlighting its severe threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:-:*:*:*:*:*:* | ||
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p1:*:*:*:*:*:* | ||
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p10:*:*:*:*:*:* | ||
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p11:*:*:*:*:*:* | ||
8.8.15CPE matchmatch criteria | cpe:2.3:a:synacor:zimbra_collaboration_suite:8.8.15:p12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.